DISA STIG — Windows Server 2022 V2R4
Audit-Policy STIG Requirements
The Windows event codes that give an auditor direct evidence for each DISA STIG audit-policy requirement below.
Scope: Covers the WN22-AU-series audit-subcategory requirements — the STIG rules directly asking whether a specific Advanced Audit Policy subcategory is enabled. The broader STIG (275 rules total: 31 CAT I, 232 CAT II, 12 CAT III) covers configuration hardening — file permissions, password policy, removed services — that's a full compliance scan's job, not a log-evidence one, and isn't attempted here.
Version: Microsoft Windows Server 2022 STIG V2R4 (released April 2, 2025), current as of this catalog. Every rule below cites its official DISA Vuln-ID.
Prerequisite: None of these subcategory rules take effect unless "Audit: Force audit policy subcategory settings to override audit policy category settings" (WN22-SO-000050) is enabled first — see the gap section below.